Huamanities last exam solved for
the unmanned revolution.

A controlled comparison of five command-link protocols across eight contested-spectrum scenarios, measuring delivery, key compromise and recovery under sustained electronic attack.

§ 01

A benchmark for contested-spectrum command links

Encryption tactical links all need the same thing: a command that arrives, verified, while the operation is under attack. We built this benchmark to measure how far standard cryptographic stacks fall when the channel is jammed, corrupted and reordered at once — and where it fails.

Standard tactical crypto fails the moment bits get corrupted. Handshakes stall, session keys are lost, and re-establishing trust takes longer than the window the operation has. Under sustained jamming, a link that is nominally secure is operationally absent.

Lineage authenticates every message, reconstructs through jamming, packet loss and bit corruption, and limits capture exposure to a single message rather than the fleet.

Figure 01

Command delivery %

AES-256-GCM

41

ChaCha20-Poly

28

X25519 + KEM

12

ML-KEM+AES

9

Lineage

99

Command delivery under combined electronic-warfare conditions. Higher is better, averaged across all eight scenarios.

§ 03

How the benchmark was built

Every protocol was measured against the same combined attack: random packet loss, per-bit corruption, burst jamming and reorder simultaneously, scaled from light to severe. Numbers are measured on the same reference implementation and reproducible from the parameters below.

Attack model

Applied simultaneously

{
“loss”: “10% – 60%”,
“ber”: “1e-5 – 1e-2”,
“burst_jam”: true,
“reorder”: true,
“applied”: “simultaneously”
}

§ 04

Results

Surface RF

Ground-to-air datalink

Subsurface acoustic

UUV, undersea channel

Submarine VLF

Very low frequency

Light

Moderate

Heavy

ATTACK MODEL

10% loss · 0.1% BER · burst jam · reorder

Lineage

66%

AES-PSK

44%

AES-GCM

26%

ECDH+GCM

12% · DEAD

ML-KEM+GCM

0% · DEAD

Even at the lightest setting the rotating protocols are already dying. Lineage leads at 66%.

ORANGE LINEAGE GREY OTHER PROTOCOLS RED SESSION DEAD

Command delivery rate (%) per scenario. Values are means across 500 trials per condition; higher is better.

§ 05

What the numbers show

01

Session protocols cliff to zero, Lineage degrades gracefully

Handshake protocols fall entirely below moderate attack because the round-trip never completes. Lineage has no handshake to interrupt and no session to hold, so it remains delivering where others degrade to nothing.

02

Per-message keys contain compromise

Every message is encrypted with a single-use key from an isolated, platform-specific reservoir. Capture a platform and you learn nothing about the rest of the fleet.

03

Overhead is eight bytes, not minutes

Lineage adds eight bytes per packet against a 2.3 KB handshake for the post-quantum stack. Less to send, less to jam, less to lose.

04

Contested spectrum is unsolved for standard crypto

Under the fully combined condition, every benchmarked protocol except Lineage drops into single digits. The failure is not marginal — it is total.

§ 06

The threat landscape

Three forces are converging on the tactical link.

Electronic warfare is the dominant cause of loss. The majority of drone losses in contested environments come from EW, not kinetic fire. When the spectrum is denied, session-based encryption collapses before the airframe does.

Adversaries harvest now to decrypt later. Encrypted traffic recorded today can be opened once the mathematics gives way. Every message sent under a computational cipher is a message an adversary can store against a future break.

One capture exposes the campaign. Shared session keys and fleet-wide pre-shared keys mean a single captured platform can expose interception, replay or decryption across the fleet. The exposure is not one drone. It is the operation.

The cryptanalytic frontier is no longer slow. For decades the rate of progress against deployed ciphers was treated as a near-constant. That assumption no longer holds.

§ 07

AI-accelerated cryptanalysis

In July 2026 the timeline changed.

On 28 July 2026, Anthropic disclosed that its restricted frontier model found a structural flaw in HAWK, the only lattice-based candidate remaining in NIST’s third-round post-quantum signature process. It cut the effective key strength roughly in half, reducing HAWK-256 key recovery from a 2^64 to a 2^38 work factor. The released implementation recovers signing-equivalent keys in under four hours on a single server.

The same model invented a new technique, the Möbius Bridge, that made an existing attack on a reduced-round AES-128 variant between 200 and 800 times faster. It worked largely on its own, over roughly three days.

Neither result breaks deployed encryption. HAWK is not fielded. The AES result targets a deliberately weakened seven-round research variant, not the full cipher running in production systems. No practical break of deployed AES or PQC is claimed.

What changed is not that a cipher fell. What changed is the rate. A machine internalised the published literature, generated new attacks from it, and pushed them past where two years of expert human review had reached. The pace of cryptanalytic progress, long treated as a slow and predictable constant in migration planning, is now a variable no programme currently models.

Computational security rests on a wager. It assumes certain mathematical problems stay hard for long enough. AES, RSA, ECC and every post-quantum scheme make that wager. The wager may hold for years. The odds now move faster than the platforms they protect are built to last.

Lineage does not make that wager. Its architecture targets bounded information-theoretic security for the protected traffic class. There is no hardness assumption to erode, because security does not rest on one. A faster attack, a stronger model or a working quantum computer changes nothing about a key that is used once and never reused.

This is the difference between a cipher that is currently unbroken and a construction with nothing to break. On a platform expected to fly, sail or dive for years, that difference is the whole risk.

§ 08

Compliance and the post-quantum transition

The transition is mandated, not optional. NIST deprecates RSA, ECC and Diffie-Hellman by 2030 and prohibits them by 2035. NSA CNSA 2.0 and NCSC guidance are already in force. Australia mandates post-quantum cryptography by 2028. These dates are the de facto compliance deadlines for allied defence procurement.

Retrofitting PQC meets the deadline. It does not change the security class. A Kyber or Dilithium retrofit swaps one set of hardness assumptions for another. It satisfies the standard and inherits the standard’s exposure to the moving frontier.

Lineage is built for the transition and past it. It carries a post-quantum-secure property by default, and its underlying architecture reaches a stronger class than any computational scheme can offer. Provision once. No forced migration when the next assumption weakens.

§ 09

Integration

Lineage sits between the transport and the platform. It runs as an inline layer on the command path: transport, then Lineage, then autonomy. It does not replace the radio and it does not rebuild the autonomy stack.

It is format-agnostic. It protects MAVLink, CRSF, SBUS and raw video without parsing the payload. Eight bytes of overhead per packet. Less to send, less to jam, less to lose.

No platform firmware changes. The platform is not modified. Keys are provisioned once. Integration is measured in days, not the months a radio replacement demands.

The security engine runs on a small firmware module that imposes a steady, low-energy load rather than compute spikes. Longer endurance, greater range, less thermal stress than key-establishment schemes that spike power on every handshake.

Anti-jam behaviour is intrinsic, not configured. There is no handshake and no session, so there is nothing for the jammer to interrupt. The link reconstructs itself message by message, which is what the benchmark above measures.

§ 10

What this benchmark does not say

The benchmark measures command delivery on a fixed set of scenarios. Different channel conditions would produce different figures. Results reflect the reference implementation at the time of testing, not field conditions.

It is a controlled comparison, not a trial validation. Operational qualification remains with the integrator and the end customer. We publish the parameters so the numbers can be challenged.

Full dataset on request

Request the complete benchmark file

Per-scenario traces, trial distributions and the reference implementation notes are available to qualified programmes.